CVE-2000-0258: Input Validation

Published Apr 12, 2000
·
Updated

IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.

Affected Software

2 affected components
Microsoft Internet Information Server=4.0
Microsoft Internet Information Services=5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Restrict external access to affected Microsoft Internet Information Services (IIS 4.0 and 5.0) hosts at the network perimeter using firewall rules or ACLs. Deploy a WAF or reverse proxy to detect and block or drop requests that contain an excessive number of percent-encoded (escaped) characters and to rate-limit requests per client to mitigate denial-of-service attempts.

  2. Operational

    Monitor IIS logs for large volumes of requests containing many escaped (percent-encoded) characters. When detected, block or throttle offending source IPs, isolate affected hosts as needed, and follow incident response procedures (including restarting IIS if required). Subscribe to vendor/security advisories and apply any vendor-supplied patches or upgrades for IIS 4.0/5.0 when they become available.

Event History

Apr 12, 2000
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityWeaknessAffected Software
Jun 2, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2000-0258?

CVE-2000-0258 is classified as a denial of service vulnerability affecting IIS 4.0 and 5.0.

2

How do I fix CVE-2000-0258?

To mitigate CVE-2000-0258, it is recommended to upgrade to a newer version of IIS that is not vulnerable to this issue.

3

What software versions are affected by CVE-2000-0258?

CVE-2000-0258 affects Microsoft Internet Information Server 4.0 and Internet Information Services 5.0.

4

Can CVE-2000-0258 lead to server downtime?

Yes, CVE-2000-0258 can lead to server downtime by causing denial of service through excessive requests.

5

Is there any workaround for CVE-2000-0258?

There are no known workarounds for CVE-2000-0258 other than updating the affected software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203